10-30-2005 07:29 AM - edited 03-09-2019 12:52 PM
Hi all,
our company newly bought a Tandberg video conferencing device i have to place that video conferncing device next to the firewall (515 ver 6.3(3))
for that i have to enable h.323 protocol
for that which ports i have to open in a firewall please give me your suggestions
10-31-2005 01:38 AM
hi
i think you can use fixup protocol for opening both h.323 as well as other multimedia applications in your PIX firewall.
Also refer this link for more info on the same...
http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_62/config/fixup.htm#xtocid21
regds
11-01-2005 12:23 AM
Hi ,
I used the fixup protocol to open the ports but the fiewall is still blocking something
fixup protocol h323 h225 1720
fixup protocol h323 h225 2776
fixup protocol h323 h225 2777
fixup protocol h323 h225 5555-5556
fixup protocol h323 ras 1718-1719
is this enough for VC or i have to open more ports
please give me your suggestions
11-02-2005 08:57 AM
Hi,
The tandberg VideoConf. use H.323 V4 by default. The fixup in the pix is for H.323 V2.
The videoConf box is trying to encrypt the conference call(default behavior). You must disable encryption(H.323 V4). If it does not work...look at the codec on the box, the problem is always there. (many H.*** are not supported on pix)
I have 4 of them on campus...a challenge every time :) I might be able to find a working config if needed.
11-02-2005 07:51 PM
Hi domnic,
are you talking about the bordercontroller?
can you suggest me which ports i have open in pix
for video conference ?
11-03-2005 07:06 AM
No, I'm not talking about border controller. You can get a videoconferencing to work with a PIX without it. The pix does'nt support those...from tandberg website...
"TANDBERG supports all of the following encryption standards: AES, DES, H.233, H.234 and H.235 with an extended Diffie-Hellman key distribution on H.323, H.320 and leased lines."
Simply disable those in the end device and the fixup h.323 on the pix will do the job. If you need encryption, you will have to use(buy) the border controler.
(If you disable encryption on your side, the other end will negotiate a connection without encryption too)
11-05-2005 12:18 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide